Bridging OPC UA Tags from WinCC into SIMATIC S7-400 PLC Logic

David Krause12 min read
OPC / OPC UASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: Why WinCC OPC UA Tags Do Not Auto-Reach STEP 7

The OPC UA WinCC Channel — provided as an add-on for WinCC V7 by third parties such as Allmendinger — reads items from any external OPC UA server into the WinCC Tag Management. Those tags exist only inside the WinCC runtime database; they are not republished into STEP 7 / SIMATIC Manager symbol tables, data blocks, or the S7 process image. A SIMATIC S7-410-5H CPU executing a level-based pump-start cannot read a WinCC tag directly. The value must first cross the WinCC ↔ PLC boundary over one of three supported transports: an OPC UA-capable CP 443-1 communications processor, a SIMATIC Net OPC UA Server on a PC station, or a direct S7 connection from a third-party OPC UA gateway to the CPU's integrated PROFINET/Industrial Ethernet interface.

Comparison of the three supported architectures
Transport Hardware/Software Required Typical Latency Redundancy Best Fit
CP 443-1 OPC UA (server role) CP 443-1 Advanced or RN variant, firmware with OPC UA capability 100–500 ms RN variant for H-system redundancy Rack-mounted, deterministic DB exposure
SIMATIC Net OPC UA Server SIMATIC Net V18+ on Windows; S7 connection to PLC 200 ms – 2 s PC-side software redundancy Existing engineering / WinCC server PC
OPC UA → S7 gateway HMS Anybus, Softing, Kepware, SCALANCE 50–250 ms Vendor-dependent WinCC removed from loop, sub-200 ms determinism
Important: The OPC UA WinCC Channel is a client driver that runs inside WinCC V7. WinCC V7 does not expose an OPC UA server by default at the same level as the WinCC Unified / WinCC Professional OPC UA server, which is documented separately under TIA Portal V20 — Configure WinCC OPC UA Server (RT Professional). Confirm the OPC UA server role on whichever WinCC you operate before designing the data path.

Prerequisites

  1. STEP 7 V5.5 / SIMATIC Manager SPx (or TIA Portal V18+ if migrated). The S7-410-5H is configurable from both, but STEP 7 V5.5 is the canonical tool for S7-400 H systems.
  2. WinCC V7.4 SP3 or later runtime, with the OPC UA WinCC Channel installed and licensed. Reference the third-party channel documented in OPC UA Extension for SIMATIC WinCC — Unified Automation case study.
  3. Verified TCP reachability between the WinCC station and the third-party OPC UA server (default opc.tcp://<host>:4840; port 4841 for OPC UA over HTTPS).
  4. Successful import of the third-party OPC UA tags into WinCC Tag Management — confirm live values in WinCC Explorer under "Tags".
  5. One of: a CP 443-1 communications processor with OPC UA capability in the S7-410-5H rack; a SIMATIC Net PC installation; or an OPC UA gateway device.
  6. Defined DB layout in STEP 7 where incoming OPC UA values will be stored (for example, DB200 with level REAL at byte offset 0).

Method 1 — CP 443-1 OPC UA Card

The CP 443-1 family of communications processors plugs into the S7-400 rack and exposes an OPC UA server directly on the plant network. Once configured, any OPC UA client — including STEP 7's own OPC UA capability via the SIMATIC Manager "OPC" entry, or the OPC UA WinCC Channel — can read the PLC's DB variables and write them back.

Hardware selection

Article Number Description OPC UA Server
6GK7 443-1EX30-0XE0 CP 443-1 (basic) No native OPC UA — basic variants only
6GK7 443-1GX30-0XE0 CP 443-1 Advanced Yes — firmware ≥ V3.x adds OPC UA
6GK7 443-1UX00-0XE0 CP 443-1 RN (redundancy) Yes — designed for S7-400 H systems

Verify OPC UA licensing in the CP's STEP 7 Hardware Configuration under "Properties → OPC UA". The Advanced and RN variants ship an OPC UA server function block and web-based management; the basic EX30 does not. Cross-check the catalog page on the Siemens Industry Mall (S7-400 Communication category) for the firmware version that introduced OPC UA on your specific part number before purchase.

STEP 7 configuration

  1. In SIMATIC Manager, open the S7-410-5H station and double-click the CP 443-1 slot.
  2. Assign an IP address and subnet that match the OPC UA client network. Enable "OPC UA Server" under "Properties → OPC UA".
  3. Configure the server endpoint: port (default 4840), security policy (None, Basic128Rsa15, Basic256Sha256 — pick the strongest your client supports), and authentication mode (Anonymous / Username-Password / Certificate).
  4. Under "Symbolic address space", map the STEP 7 DBs and I/O you want to expose as OPC UA nodes. Example: DB200,DBD0:REAL = LevelValue.
  5. Compile and download HW Config to the rack. Restart the CP if prompted.
  6. Open a browser to https://<CP-IP>/opcua to verify the endpoint is reachable and the namespace is published.

WinCC side configuration

  1. In WinCC Explorer, right-click "Tag Management" → "Add new driver".
  2. Add the "OPC UA WinCC Channel". Configure the connection to opc.tcp://<CP-IP>:4840.
  3. Browse the server namespace and select the exposed DB variables. Click "Add tags".
  4. Once imported, the WinCC tags read directly from the S7-410-5H through the CP. The PLC program writes the level value into DB200 and the WinCC tag reflects it on the next OPC UA publishing cycle.
Data direction note: This pattern inverts the original requirement — instead of bringing the OPC UA tag into the PLC, you expose the PLC's DB to WinCC. If the requirement is for the PLC to read the third-party OPC UA server directly (e.g. for autonomous pump-start logic), skip to Method 3.

Method 2 — SIMATIC Net OPC UA Server on a PC Station

SIMATIC Net is the Siemens suite that provides an OPC UA server running on a Windows PC and bridging to S7 PLCs over Industrial Ethernet (ISO-on-TCP / S7 communication). This is the right choice when you already operate an engineering station or WinCC server PC and want to consolidate OPC UA traffic through it.

Installation

  1. Install SIMATIC Net V18 (or matching your STEP 7 / TIA Portal). Components: "SIMATIC Net PC Software", "OPC UA Server".
  2. Run "Station Configuration Editor" and add an "OPC UA Server" station. Configure the PC's network adapter as the access point.
  3. In STEP 7, open "PC Station" and add the same OPC UA server to the PC station's hardware configuration so the S7 connection table matches.
  4. Configure an S7 connection from the PC station to the S7-410-5H. Specify CPU IP, rack, slot.

Mapping DBs to OPC UA nodes

  1. Open the SIMATIC Net "OPC UA Server Configuration" tool.
  2. Browse the S7 connection's symbol table or imported DBs. Right-click the desired DB elements (e.g. DB200.DBD0:REAL "LevelValue") and enable "Expose as OPC UA".
  3. Save and restart the OPC UA server service.
  4. Verify the endpoint via UA Expert or the browser at https://localhost:4840.

Bidirectional flow

External OPC UA clients write to the SIMATIC Net server, which in turn writes to the S7-410-5H's DB200. The PLC's OB1 cycle reads DB200.DBD0 (REAL), compares against the high-level threshold DB200.DBD4 (REAL), and sets BOOL output Q0.0 to start the pump. Complete STL/Statement List logic:

// OB1 - Pump start logic
// Inputs:
//   DB200.DBD0  : LevelValue (REAL, from OPC UA)
//   DB200.DBD4  : HighSetpoint (REAL)
// Outputs:
//   Q0.0        : PumpRun

A "Tag_Enable"
L "DB200".LevelValue
L "DB200".HighSetpoint
>R
S Q 0.0

The SIMATIC Net method scales well: multiple OPC UA clients can subscribe simultaneously without consuming CP 443-1 connections, and the OPC UA server can be configured for PC-side redundancy. For a working reference of an OPC UA client to WinCC SCADA, see HMS Networks — Communicating to a Siemens WINCC SCADA via OPC UA.

Method 3 — Direct OPC UA Client to S7-410-5H CPU

The S7-410-5H CPU does not natively expose an OPC UA server on its integrated PROFINET/Industrial Ethernet port. To read OPC UA tags directly from a third-party OPC UA server without WinCC in the path, you need either:

  • An S7-400 add-on module that exposes OPC UA — verify the latest catalog entries on the Siemens Industry Mall under SIMATIC S7-400 Communication.
  • A standalone OPC UA gateway device (HMS Anybus, Softing, Kepware, Siemens SCALANCE) that converts OPC UA to S7 TCP and writes values into the S7-410-5H's DBs.

Reference implementation using an HMS Anybus X-gateway OPC UA client

  1. Configure the Anybus as an OPC UA client pointing at the third-party OPC UA server URL.
  2. Map OPC UA node IDs to the Anybus's internal register buffer.
  3. Enable the Anybus's S7 client role and configure an S7 connection to the S7-410-5H (rack/slot, DB number, byte offset).
  4. The Anybus periodically writes OPC UA values into DB200.DBD0 of the S7-410-5H.
  5. The PLC program runs the level comparison logic natively without WinCC in the loop.
Vendor documentation: HMS Networks publishes a Siemens WinCC SCADA OPC UA application note at Communicating to a Siemens WINCC SCADA via OPC UA for the equivalent path when WinCC is the OPC UA client side. For the WinCC V7 channel itself, see the Siemens WinCC V7 OPC UA documentation PDF.

Verification Procedure

  1. Network reachability: From the WinCC / SIMATIC Net PC, connect UA Expert to opc.tcp://<server>:4840. Confirm "Connected" and "Browse succeeds".
  2. WinCC tag values: In WinCC Explorer → Tags, right-click the imported OPC UA tag → Properties. Trigger a graphics update and confirm the value matches the third-party OPC UA server.
  3. S7 DB value: In SIMATIC Manager, open DB200 online view. Press F5 (refresh) and confirm the LevelValue reflects the OPC UA tag value within the configured update cycle.
  4. Logic execution: Force the level tag in the OPC UA server above and below the high setpoint and confirm Q0.0 sets/resets in OB1 online view.
  5. CP 443-1 diagnostics: In STEP 7, open "PLC → Diagnostic/Setting → Module Information" for the CP 443-1. Inspect "OPC UA Server" diagnostics for connection count, error count, and last error code.
  6. WinCC diagnostics: In the OPC UA WinCC Channel diagnostics applet, confirm subscription state "Good" and last error code = 0x00000000.
  7. Cycle timing: In SIMATIC Manager open "PLC → Monitor/Modify" on OB1 and verify the >R comparison executes each scan without skipped cycles.

Troubleshooting Matrix

Common OPC UA WinCC Channel to S7-410-5H faults
Symptom Likely Root Cause Remediation
WinCC tag shows "Bad Communication" 0x80050000 OPC UA client cannot reach endpoint; firewall on TCP 4840 Open port; verify URL with UA Expert; check certificate trust store
Tag updates in WinCC but DB200 stays 0.0 in PLC No S7 write path configured, only WinCC↔OPC UA direction Add S7 connection from PC station or CP, map DB200 in OPC UA server
CP 443-1 diagnostics: "OPC UA Server not active" OPC UA not licensed or wrong firmware variant (basic EX30 installed) Confirm part number supports OPC UA, install license, upgrade firmware to V3.x+
STEP 7 online DB shows correct value but Q0.0 never sets Ladder logic comparing wrong operand; type mismatch REAL vs INT Verify DB200.DBD0 is REAL, threshold DB200.DBD4 is REAL, >R instruction used
CP 443-1 connection drops after H-system failover RN variant not used, only a single CP installed Replace with 6GK7 443-1UX00-0XE0 RN variant; configure both H-CP slots in HW Config
OPC UA WinCC Channel license not found at startup Add-on DLL not registered; license file missing Re-register DLL with regsvr32 <channel>.dll; reapply license key from Allmendinger
Subscription quality "Good" but values lag by >5 seconds Publishing interval set to 5000 ms; OPC UA server slow sampling Lower publishing interval to 250 ms; verify OPC UA server's sampling rate
SIMATIC Net "S7 connection down" after PC restart Station Configuration Editor not set to autostart OPC UA service Set service to Automatic startup type in Windows Services; check S7ONLINE access point

Performance and Update Cycle Sizing

OPC UA subscriptions are governed by the publishing interval (default 1000 ms) and the sampling interval (default 250 ms). On an S7-410-5H with a CP 443-1 UX00, expect the following end-to-end latency:

  • Third-party OPC UA server → WinCC tag: 250–1000 ms (subscription interval).
  • WinCC tag → S7 DB write (via SIMATIC Net): 200–500 ms per write cycle.
  • PLC OB1 scan: 10–50 ms.
  • Total worst case: ~1.5 s.

For pump-start interlocks where the third-party level signal originates from a remote SCADA, a 1.5-second end-to-end delay is acceptable. If tighter determinism is required (sub-200 ms), drop WinCC from the loop and use an OPC UA → S7 gateway at the plant network edge.

Security Considerations

  1. Issue machine certificates from a plant CA, not the OPC UA server's self-signed cert.
  2. Enable security policy Basic256Sha256 or higher.
  3. Restrict the endpoint to TLS 1.2 minimum.
  4. Use dedicated service accounts (UsernameIdentityToken) for the WinCC OPC UA client subscription.
  5. On the CP 443-1, enable the integrated firewall and limit OPC UA traffic to the WinCC station's IP via ACL.
  6. Audit subscription list quarterly to ensure no orphan clients remain connected.
  7. Disable Anonymous authentication on production CP 443-1 OPC UA server endpoints.

Frequently Asked Questions

Can the OPC UA WinCC Channel write tags directly into a STEP 7 data block?

No. The OPC UA WinCC Channel is a WinCC-side client driver; it populates WinCC tags only. To move those values into an S7-410-5H data block you must add an S7 transport — either a CP 443-1 OPC UA server, a SIMATIC Net OPC UA Server, or an OPC UA-to-S7 gateway.

Which CP 443-1 part number supports OPC UA?

The CP 443-1 Advanced (6GK7 443-1GX30-0XE0) and the RN variant for H-systems (6GK7 443-1UX00-0XE0) expose an OPC UA server. The basic EX30 does not. Confirm the OPC UA server firmware load against the Siemens Industry Mall catalog page for your specific hardware revision before ordering.

Does the S7-410-5H CPU itself expose an OPC UA server on its PROFINET port?

No, the integrated Ethernet port of the S7-410-5H CPU does not host an OPC UA server by default. You need either a CP 443-1 OPC UA module, a SIMATIC Net PC software gateway, or a third-party OPC UA-to-S7 gateway device to make DB variables reachable over OPC UA.

Is the OPC UA WinCC Channel from Allmendinger compatible with WinCC V7.5?

Yes. The third-party channel supplied by Allmendinger is documented for WinCC V7.x in the Unified Automation case study and the Siemens WinCC V7 OPC UA documentation. Verify the channel version against your WinCC SP level before installation.

What is the fastest end-to-end latency from OPC UA tag to PLC output?

With a CP 443-1 OPC UA server and an OPC UA publishing interval of 100 ms plus an OB1 scan of 20 ms, expect roughly 150 ms. Through WinCC and SIMATIC Net the latency is typically 1–2 seconds due to two hops. For sub-100 ms determinism use a direct OPC UA-to-S7 gateway.

Can I keep the WinCC OPC UA Channel and still run the PLC decision logic autonomously?

Yes. Use the CP 443-1 OPC UA server (Method 1) so the PLC writes the level value into DB200. The PLC program reads DB200 and runs the pump-start logic natively. WinCC continues to read the same DB through its own OPC UA subscription for HMI display, without affecting the PLC scan.

Back to blog